Courseiva
Authentication and VPN →easyMultiple Choice

NSE4 Authentication and VPN Practice Question

What is the primary function of Fortinet Single Sign-On (FSSO) in a FortiGate deployment?

⚠ Common exam trap

A common mix-up: candidates confuse FSSO with direct authentication methods (like RADIUS or LDAP) and assume it performs user authentication, when in fact it only collects existing authentication events from Active Directory for policy enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To collect user login events from Active Directory for user-based policies

Fortinet Single Sign-On (FSSO) is designed to collect user login events from Active Directory (AD) domain controllers. It monitors authentication traffic (e.g., via NetAPI or polling the AD security event log) to map IP addresses to usernames, enabling FortiGate to enforce user-based firewall policies without requiring users to manually authenticate to the firewall.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To provide two-factor authentication using FortiToken

    Why it's wrong here

    FortiToken is a separate FortiOS feature used for two-factor authentication, requiring users to provide a one-time passcode in addition to their credentials. Fortinet Single Sign-On (FSSO) does not perform authentication or token validation; it passively monitors Active Directory for existing user login events to correlate usernames with IP addresses for policy enforcement. Therefore, this option confuses a multi-factor authentication mechanism with a directory-based single sign-on solution.

  • ✗

    To sync FortiGate configuration with Active Directory

    Why it's wrong here

    FSSO is not a configuration management or synchronization service; it does not push firewall policies, objects, or settings to Active Directory, nor does it pull directory schema changes to update FortiGate. Instead, a collector agent polls domain controllers for security event logs or uses NetAPI to discover successful user logons, then relays that session data to the FortiGate. Configuration synchronization is handled by tools like FortiManager or FortiGate's own clustering/fabric features, so this option misrepresents the core function of FSSO.

  • ✗

    To authenticate users against a RADIUS server

    Why it's wrong here

    RADIUS is an authentication protocol that validates user credentials against a backend server, but FSSO does not act as a RADIUS client or server. FSSO is purely a single sign-on mechanism that leverages the fact that users already authenticated to Active Directory at the desktop; it captures those existing login sessions and maps them to IP addresses. Unlike RADIUS, which processes Access-Request/Access-Accept exchanges, FSSO only consumes authentication event data that Active Directory has already generated, so this option inaccurately describes FSSO as an authentication method.

  • ✓

    To collect user login events from Active Directory for user-based policies

    Why this is correct

    FSSO's primary function is to automatically identify users based on their existing Active Directory login events and map those events to the source IP address of the client machine. A collector agent on the network monitors domain controller security logs or uses RPC calls to track successful user logons, then sends this mapping to the FortiGate. This enables the firewall to enforce user-based policies without prompting for credentials, because the user has already been authenticated by AD. The wrong answers describe other security features, but this is the exact mechanism FSSO provides.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.